CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2017-0499.html - () http://rhn.redhat.com/errata/RHSA-2017-0499.html -
References () http://www.debian.org/security/2017/dsa-3810 - () http://www.debian.org/security/2017/dsa-3810 -
References () http://www.securityfocus.com/bid/96767 - () http://www.securityfocus.com/bid/96767 -
References () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html - () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html -
References () https://crbug.com/671932 - () https://crbug.com/671932 -
References () https://security.gentoo.org/glsa/201704-02 - () https://security.gentoo.org/glsa/201704-02 -

07 Nov 2023, 02:48

Type Values Removed Values Added
References (DEBIAN) http://www.debian.org/security/2017/dsa-3810 - Third Party Advisory () http://www.debian.org/security/2017/dsa-3810 -
References (BID) http://www.securityfocus.com/bid/96767 - Broken Link () http://www.securityfocus.com/bid/96767 -
References (CONFIRM) https://crbug.com/671932 - Issue Tracking, Patch, Vendor Advisory () https://crbug.com/671932 -
References (GENTOO) https://security.gentoo.org/glsa/201704-02 - Third Party Advisory () https://security.gentoo.org/glsa/201704-02 -
References (REDHAT) http://rhn.redhat.com/errata/RHSA-2017-0499.html - Third Party Advisory () http://rhn.redhat.com/errata/RHSA-2017-0499.html -
References (CONFIRM) https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html - Vendor Advisory () https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop.html -

Information

Published : 2017-04-24 23:59

Updated : 2024-11-21 03:26


NVD link : CVE-2017-5042

Mitre link : CVE-2017-5042

CVE.ORG link : CVE-2017-5042


JSON object : View

Products Affected

linux

  • linux_kernel

apple

  • macos

microsoft

  • windows

google

  • chrome
  • android

redhat

  • enterprise_linux_desktop
  • enterprise_linux_workstation
  • enterprise_linux_server

debian

  • debian_linux
CWE
CWE-311

Missing Encryption of Sensitive Data